Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 294

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Fed holds interest rates steady: Here's what that means for credit cards, savings rates, mortgages and car loans
JetBlue to reduce Newark, LaGuardia footprint as it forges ahead in Fort Lauderdale
Inside India newsletter: Anthropic curbs ignite AI debate in India — efforts 'too slow, way too small'
Widow's Bay: We Hope You Enjoyed Your Time
Mr. Queen: Full season
Earth Wind and Fire - To Be Celestial vs. That's the Weight of the World
Here are the five big takeaways from Kevin Warsh's first meeting as Fed chairman
Oil falls as International Energy Agency forecasts supply glut next year after U.S.-Iran deal
Google Gemini co-lead Noam Shazeer leaves for OpenAI
Defense contractors would be barred from buying back their stock in bill approved by Senate panel